Static | ZeroBOX

PE Compile Time

1992-06-20 07:22:17

PE Imphash

9f4693fc0c511135129493f2161d1e86

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
CODE 0x00001000 0x000072c0 0x00007400 6.52114932089
DATA 0x00009000 0x00000218 0x00000400 3.15169834056
BSS 0x0000a000 0x0000a899 0x00000000 0.0
.idata 0x00015000 0x00000864 0x00000a00 4.17385976895
.tls 0x00016000 0x00000008 0x00000000 0.0
.rdata 0x00017000 0x00000018 0x00000200 0.206920017787
.reloc 0x00018000 0x000005cc 0x00000600 6.43311735034
.rsrc 0x00019000 0x00001400 0x00001400 3.83056331735

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00019150 0x000010a8 LANG_RUSSIAN SUBLANG_RUSSIAN data
RT_RCDATA 0x0001a208 0x000000ac LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_RCDATA 0x0001a208 0x000000ac LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x0001a2b4 0x00000014 LANG_RUSSIAN SUBLANG_RUSSIAN data

Imports

Library kernel32.dll:
0x4150ec VirtualFree
0x4150f0 VirtualAlloc
0x4150f4 LocalFree
0x4150f8 LocalAlloc
0x4150fc GetVersion
0x415100 GetCurrentThreadId
0x415104 GetThreadLocale
0x415108 GetStartupInfoA
0x41510c GetLocaleInfoA
0x415110 GetCommandLineA
0x415114 FreeLibrary
0x415118 ExitProcess
0x41511c WriteFile
0x415124 RtlUnwind
0x415128 RaiseException
0x41512c GetStdHandle
Library user32.dll:
0x415134 GetKeyboardType
0x415138 MessageBoxA
Library advapi32.dll:
0x415140 RegQueryValueExA
0x415144 RegOpenKeyExA
0x415148 RegCloseKey
Library oleaut32.dll:
0x415150 SysFreeString
0x415154 SysReAllocStringLen
Library kernel32.dll:
0x41515c TlsSetValue
0x415160 TlsGetValue
0x415164 LocalAlloc
0x415168 GetModuleHandleA
Library advapi32.dll:
0x415170 RegSetValueExA
0x415174 RegOpenKeyExA
0x415178 RegCloseKey
Library kernel32.dll:
0x415180 WriteFile
0x415184 WinExec
0x415188 SetFilePointer
0x41518c SetFileAttributesA
0x415190 SetEndOfFile
0x415198 ReleaseMutex
0x41519c ReadFile
0x4151a4 GetTempPathA
0x4151a8 GetShortPathNameA
0x4151ac GetModuleFileNameA
0x4151b4 GetLocalTime
0x4151b8 GetLastError
0x4151bc GetFileSize
0x4151c0 GetFileAttributesA
0x4151c4 GetDriveTypeA
0x4151c8 GetCommandLineA
0x4151cc FreeLibrary
0x4151d0 FindNextFileA
0x4151d4 FindFirstFileA
0x4151d8 FindClose
0x4151dc DeleteFileA
0x4151e0 CreateMutexA
0x4151e4 CreateFileA
0x4151e8 CreateDirectoryA
0x4151ec CloseHandle
Library gdi32.dll:
0x4151f4 StretchDIBits
0x4151f8 SetDIBits
0x4151fc SelectObject
0x415200 GetObjectA
0x415204 GetDIBits
0x415208 DeleteObject
0x41520c DeleteDC
0x415210 CreateSolidBrush
0x415214 CreateDIBSection
0x415218 CreateCompatibleDC
0x415220 BitBlt
Library user32.dll:
0x415228 ReleaseDC
0x41522c GetSysColor
0x415230 GetIconInfo
0x415234 GetDC
0x415238 FillRect
0x41523c DestroyIcon
0x415240 CopyImage
0x415244 CharLowerBuffA
Library shell32.dll:
0x41524c ShellExecuteA
0x415250 ExtractIconA

This program must be run under Win32
.idata
.rdata
P.reloc
P.rsrc
YZ]_^[
YZ]_^[
_^[YY]
YZ]_^[
~KxI[)
SOFTWARE\Borland\Delphi\RTL
FPUMaskValue
_^[YY]
HBITMAP
YXZQRPR
R;P P|
IVXLCDMT
_^[YY]
_^[YY]
XH;XH~
9PD}-RP
PH9PL~
KH+KLQ
;CHRQ~
RP;P ~
tSPRQj
_^[YY]
QQQQQS
\PROGRA~1\
QQQQQQSVW
_^[YY]
QQQQQQS3
QQQQQQ
QQQQQQSV
Runtime error at 00000000
0123456789ABCDEF
kernel32.dll
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetVersion
GetCurrentThreadId
GetThreadLocale
GetStartupInfoA
GetLocaleInfoA
GetCommandLineA
FreeLibrary
ExitProcess
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
user32.dll
GetKeyboardType
MessageBoxA
advapi32.dll
RegQueryValueExA
RegOpenKeyExA
RegCloseKey
oleaut32.dll
SysFreeString
SysReAllocStringLen
kernel32.dll
TlsSetValue
TlsGetValue
LocalAlloc
GetModuleHandleA
advapi32.dll
RegSetValueExA
RegOpenKeyExA
RegCloseKey
kernel32.dll
WriteFile
WinExec
SetFilePointer
SetFileAttributesA
SetEndOfFile
SetCurrentDirectoryA
ReleaseMutex
ReadFile
GetWindowsDirectoryA
GetTempPathA
GetShortPathNameA
GetModuleFileNameA
GetLogicalDriveStringsA
GetLocalTime
GetLastError
GetFileSize
GetFileAttributesA
GetDriveTypeA
GetCommandLineA
FreeLibrary
FindNextFileA
FindFirstFileA
FindClose
DeleteFileA
CreateMutexA
CreateFileA
CreateDirectoryA
CloseHandle
gdi32.dll
StretchDIBits
SetDIBits
SelectObject
GetObjectA
GetDIBits
DeleteObject
DeleteDC
CreateSolidBrush
CreateDIBSection
CreateCompatibleDC
CreateCompatibleBitmap
BitBlt
user32.dll
ReleaseDC
GetSysColor
GetIconInfo
FillRect
DestroyIcon
CopyImage
CharLowerBuffA
shell32.dll
ShellExecuteA
ExtractIconA
0"0*020:0B0J0R0Z0b0j0r0z0
4-595T5
8&8,848F8R8a8m8u8
9/9:9[9s9
<'<0<;<D<K<Z<a<
?2?\?e?u?}?
0(0@0L0T0k0z0
0,1P1n1~1
2$2u2|2
4#4+4O4o4
8A8Q8g8
9*929H9`9n9
9+:X:a:
< =T=\=g=
>N>R>X>\>a>h>n>v>
?%?/?7?=?K?f?{?
N0W0}0
466?6:7C7
<)<2<><E<
=/=;=B=L=V=m=~=
>/>@>J>R>Z>b>j>
?&?+?0?7?>?H?_?k?x?
0:0B0J0R0Z0b0j0r0z0
1"1*121:1B1J1R1Z1b1j1r1z1
2#202B2J2R2_2k2x2
3 323?3K3X3j3w3
4$4(4,484<4@4L4P4T4`4d4h4t4x4|4
9,;:;A;H;c;o;
:(;=;c;
=*=:=c=9>n>
1&151R1i1
:":U:t:
:2;H;b;
;Y<j<,=
1 1$1(1,1014181<1@1D1H1L1P1T1X1\1`1d1h1l1t1
004080
1 1$1(1
_^[YY]
_^[YY]
$YZ_^[
t%HtIHtm
_^[YY]
$Z]_^[
QQQQQQSVW3
QQQQQSVW
_^[YY]
TErrorRec
TExceptRec
YZ]_^[
m/d/yy
mmmm d, yyyy
:mm:ss
kernel32.dll
GetDiskFreeSpaceExA
(Z]_^[
oleaut32.dll
VariantChangeTypeEx
VarNeg
VarNot
VarAdd
VarSub
VarMul
VarDiv
VarIdiv
VarMod
VarAnd
VarXor
VarCmp
VarI4FromStr
VarR4FromStr
VarR8FromStr
VarDateFromStr
VarCyFromStr
VarBoolFromStr
VarBstrFromCy
VarBstrFromDate
VarBstrFromBool
TCustomVariantType
TCustomVariantType
Variants
EVariantInvalidOpError
EVariantTypeCastError
EVariantOverflowError
EVariantInvalidArgError
EVariantBadVarTypeErrorx
EVariantBadIndexError
EVariantArrayLockedError
EVariantArrayCreateError
EVariantNotImplError
EVariantOutOfMemoryError
EVariantUnexpectedError
EVariantDispatchError
EVariantInvalidNullOpError
_^[YY]
QQQQSV
QQQQSV
OtOt)
FSVWUQ
Mt0MtU
Smallint
Integer
Single
Double
Currency
OleStr
Dispatch
Boolean
Variant
Unknown
Decimal
ShortInt
LongWord
String
Array
ByRef
Variants
_^[YY]
_^[YY]
tagEXCEPINFO
TAlignment
taLeftJustify
taRightJustify
taCenter
Classes
TBiDiMode
bdLeftToRight
bdRightToLeft
bdRightToLeftNoAlign
bdRightToLeftReadingOnly
Classes
ssShift
ssCtrl
ssLeft
ssRight
ssMiddle
ssDouble
Classes
TShiftState
THelpContext
THelpType
htKeyword
htContext
Classes
TShortCut
TNotifyEvent
Sender
TObject
EStreamError
EFileStreamError
EFCreateError
EFOpenError
EFilerError<
EReadError
EWriteError
EClassNotFound
EResNotFound
EListError
EBitsError
EStringListError
EComponentError
EOutOfResourcesl
EInvalidOperation
TThreadList
TPersistent
TPersistent
Classes
TInterfacedPersistent
TInterfacedPersistent
Classes
TCollectionItem
TCollectionItem
Classes
TCollection
TCollection8
Classes
TOwnedCollection
TOwnedCollection
Classes
IStringsAdapter4
Classes
TStrings
TStrings
Classes
TStringItem
TStringList
TStringList0
Classes
TStreamp
TStreamH
Classes
THandleStream
TFileStream
TCustomMemoryStreamD
TMemoryStream
TStringStreamH
TResourceStream
TStreamAdapter
TClassFinder
TFiler
TReader
EThread
TThread
TComponentName(
IDesignerNotify4
Classes
TComponent
TComponentP
Classes
TBasicActionLink
TBasicAction
TBasicAction0
Classes
TIdentMapEntry
TRegGroup
TRegGroups
YZ]_^[
$Z]_^[
$Z]_^[
_^[YY]
TIntConst
_^[YY]
%s[%d]
Strings
S$_^[Y]
_^[YY]
SdZ]_^[
$Z]_^[
TPropFixup
TPropIntfFixup
_^[YY]
_^[YY]
Classes
_^[YY]
_^[YY]
QQQQQQQS
R0_^[]
_^[YY]
TPUtilWindow
TColor
EInvalidGraphic82B
EInvalidGraphicOperation
TFontPitch
fpDefault
fpVariable
fpFixed
Graphics
TFontName
TFontCharset
TFontStyle
fsBold
fsItalic
fsUnderline
fsStrikeOut
Graphics
TFontStyles
TPenStyle
psSolid
psDash
psDashDot
psDashDotDot
psClear
psInsideFrame
Graphics
TPenMode
pmBlack
pmWhite
pmCopy
pmNotCopy
pmMergePenNot
pmMaskPenNot
pmMergeNotPen
pmMaskNotPen
pmMerge
pmNotMerge
pmMask
pmNotMask
pmNotXor
Graphics
TBrushStyle
bsSolid
bsClear
bsHorizontal
bsVertical
bsFDiagonal
bsBDiagonal
bsCross
bsDiagCross
Graphics
TGraphicsObject@5B
TGraphicsObject
Graphics
IChangeNotifier4
Graphics
Graphics
Charsetx1B
Color<
Height
NameT2B
Pitch<
TPenh7B
Graphics
Mode,3B
Style<
TBrush
TBrushh8B
Graphics
ColorP4B
TCanvasP9B
TCanvas,9B
Graphics
Brush<
CopyMode
Font|7B
TGraphic
TGraphic
Graphics
TPicture
TPicture
Graphics
TSharedImage
TMetafileImage
TMetafile
TMetafilep=B
Graphics
TBitmapImage
TBitmap,?B
TBitmap
Graphics
TIconImage
Graphics
TResourceManager
_^[YY]
clBlack
clMaroon
clGreen
clOlive
clNavy
clPurple
clTeal
clGray
clSilver
clLime
clYellow
clBlue
clFuchsia
clAqua
clWhite
clMoneyGreen
clSkyBlue
clCream
clMedGray
clActiveBorder
clActiveCaption
clAppWorkSpace
clBackground
clBtnFace
clBtnHighlight
clBtnShadow
clBtnText
clCaptionText
clDefault
clGradientActiveCaption
clGradientInactiveCaption
clGrayText
clHighlight
clHighlightText
clHotLight
clInactiveBorder
clInactiveCaption
clInactiveCaptionText
clInfoBk
clInfoText
clMenu
clMenuBar
clMenuHighlight
clMenuText
clNone
clScrollBar
cl3DDkShadow
cl3DLight
clWindow
clWindowFrame
clWindowText
ANSI_CHARSET
DEFAULT_CHARSET
SYMBOL_CHARSET
MAC_CHARSET
SHIFTJIS_CHARSET
HANGEUL_CHARSET
JOHAB_CHARSET
GB2312_CHARSET
CHINESEBIG5_CHARSET
GREEK_CHARSET
TURKISH_CHARSET
HEBREW_CHARSET
ARABIC_CHARSET
BALTIC_CHARSET
RUSSIAN_CHARSET
THAI_CHARSET
EASTEUROPE_CHARSET
OEM_CHARSET
Default
E$PVSj
_^[YY]
C ;C$s
TFileFormat
TFileFormatsList
QQQQSV
kD$TdP
kD$PdP
D$LPkD$XdPV
D$HPkD$TdPV
|$( EMFt
TBitmapCanvas
TBitmapCanvas
Graphics
_^[YY]
s(;~ t8
C(_^[Y]
TPatternManagerSV
_^[YY]
TObjectListX
TComponentList
TOrderedList
TStack
TComponentListNexus
TComponentListNexus
Contnrs
GetMonitorInfoA
GetSystemMetrics
MonitorFromRect
MonitorFromWindow
MonitorFromPoint
GetMonitorInfo
DISPLAY
GetMonitorInfoA
DISPLAY
GetMonitorInfoW
DISPLAY
EnumDisplayMonitors
USER32.DLL
IHelpSelector4
HelpIntfs
IHelpSystem4
HelpIntfs
ICustomHelpViewer4
HelpIntfs
IExtendedHelpViewer(
HelpIntfs
ISpecialWinHelpViewerd
HelpIntfs
IHelpManager4
HelpIntfs
EHelpSystemException
THelpViewerNode
THelpManager
comctl32.dll
InitializeFlatSB
UninitializeFlatSB
FlatSB_GetScrollProp
FlatSB_SetScrollProp
FlatSB_EnableScrollBar
FlatSB_ShowScrollBar
FlatSB_GetScrollRange
FlatSB_GetScrollInfo
FlatSB_GetScrollPos
FlatSB_SetScrollPos
FlatSB_SetScrollInfo
FlatSB_SetScrollRange
TSynchroObject
TCriticalSection
uxtheme.dll
OpenThemeData
CloseThemeData
DrawThemeBackground
DrawThemeText
GetThemeBackgroundContentRect
GetThemePartSize
GetThemeTextExtent
GetThemeTextMetrics
GetThemeBackgroundRegion
HitTestThemeBackground
DrawThemeEdge
DrawThemeIcon
IsThemePartDefined
IsThemeBackgroundPartiallyTransparent
GetThemeColor
GetThemeMetric
GetThemeString
GetThemeBool
GetThemeInt
GetThemeEnumValue
GetThemePosition
GetThemeFont
GetThemeRect
GetThemeMargins
GetThemeIntList
GetThemePropertyOrigin
SetWindowTheme
GetThemeFilename
GetThemeSysColor
GetThemeSysColorBrush
GetThemeSysBool
GetThemeSysSize
GetThemeSysFont
GetThemeSysString
GetThemeSysInt
IsThemeActive
IsAppThemed
GetWindowTheme
EnableThemeDialogTexture
IsThemeDialogTextureEnabled
GetThemeAppProperties
SetThemeAppProperties
GetCurrentThemeName
GetThemeDocumentationProperty
DrawThemeParentBackground
EnableTheming
TCommonDialog
TCommonDialogL
Dialogs
HelpContext
OnClose
OnShowSV
Cancel
Ignore
NoToAll
YesToAll
commdlg_help
commdlg_FindReplace
WndProcPtr%.8X%.8X
TTimer
TTimer
ExtCtrls
Enabled|
Interval
OnTimerSV
Delphi Picture
Delphi Component
EIniFileException
TCustomIniFile
THashItem
IniFiles
TStringHash
THashedStringList
THashedStringList
IniFiles
TMemIniFile
TIniFile
QQQQQSV
QQQQSVW
_^[YY]
_^[YY]
ERegistryException
TRegistryS
MAPI32.DLL
TConversion
TConversionFormat
comctl32.dll
TThemeServices
Theme manager
2001, 2002 Mike Lischke
 !"#$%
TCustomEdit
TCustomEdit(1C
StdCtrls
TabStop
TScrollStyle
ssNone
ssHorizontal
ssVertical
ssBoth
StdCtrls
TCustomMemo
TCustomMemo43C
StdCtrls
StdCtrls8
Alignh~A
Alignment
Anchors
BevelEdges|sC
BevelInner tC
BevelKind|sC
BevelOuter
BiDiMode(
BorderStylex1B
Constraints
DragCursorDdC
DragKind
DragMode
Enabled
HideSelection
ImeModePsC
ImeName
Lines<
MaxLength
OEMConvert
ParentBiDiMode
ParentColor
ParentCtl3D
ParentFont
ParentShowHint
PopupMenu
ReadOnly
ScrollBars
ShowHintxdC
TabOrder
TabStop
Visible
WantReturns
WantTabs
WordWrap
OnChange
OnClicktmC
OnContextPopup
OnDblClick8hC
OnDragDrop
OnDragOver
OnEndDock
OnEndDrag
OnEnter
OnExit(gC
OnKeyDowntgC
OnKeyPress(gC
OnKeyUpLfC
OnMouseDown
OnMouseMoveLfC
OnMouseUp
OnStartDock
OnStartDrag
TMemoStrings
TMemoStrings
StdCtrls
_^[YY]
_^[YY]
THintAction
THintActionlOC
StdActns
TWinHelpViewer
_^[YY]
_^[YY]
IE(AL("%s",4),"AL(\"%0:s\",3)","JK(\"%1:s\",\"%0:s\")")
JumpID("","%s")
_^[YY]
MS_WINHELP
#32770
TCursor
TAlign
alNone
alBottom
alLeft
alRight
alClient
alCustom
Controls
TDragObject
TDragObjecth^C
Controls
TBaseDragControlObject
TBaseDragControlObject
Controls
TDragControlObject
TDragControlObjectEx
TDragDockObject<aC
TDragDockObject
Controls
TDragDockObjectEx
TControlCanvas
TControlCanvasLbC
Controls
TControlActionLink
TMouseButton
mbLeft
mbRight
mbMiddle
Controls
TDragMode
dmManual
dmAutomatic
Controls
TDragState
dsDragEnter
dsDragLeave
dsDragMove
Controls
TDragKind
dkDrag
dkDock
Controls
TTabOrder
TCaption
TAnchorKind
akLeft
akRight
akBottom
Controls
TAnchors
TConstraintSize
TSizeConstraints
TSizeConstraintsheC
Controls
MaxHeight
MaxWidth
MinHeight
MinWidth
TMouseEvent
Sender
TObject
Button
TMouseButton
TShiftState
Integer
Integer
TMouseMoveEvent
Sender
TObject
TShiftState
Integer
Integer
TKeyEvent
Sender
TObject
TShiftState
TKeyPressEvent
Sender
TObject
TDragOverEvent
Sender
TObject
Source
TObject
Integer
Integer
TDragState
Accept
Boolean
TDragDropEvent
Sender
TObject
Source
TObject
Integer
Integer
TStartDragEvent
Sender
TObject
DragObject
TDragObject
TEndDragEvent
Sender
TObject
Target
TObject
Integer
Integer
TDockDropEvent
Sender
TObject
Source
TDragDockObject
Integer
Integer
TDockOverEvent
Sender
TObject
Source
TDragDockObject
Integer
Integer
TDragState
Accept
Boolean
TUnDockEvent
Sender
TObject
Client
TControl
NewTarget
TWinControl
Boolean
TStartDockEvent
Sender
TObject
DragObject
TDragDockObject
TGetSiteInfoEvent
Sender
TObject
DockClient
TControl
InfluenceRect
MousePos
TPoint
CanDock
Boolean
TCanResizeEvent
Sender
TObject
NewWidth
Integer
NewHeight
Integer
Resize
Boolean
TConstrainedResizeEvent
Sender
TObject
MinWidth
Integer
MinHeight
Integer
MaxWidth
Integer
MaxHeight
Integer
TMouseWheelEvent
Sender
TObject
TShiftState
WheelDelta
Integer
MousePos
TPoint
Handled
Boolean
TMouseWheelUpDownEvent
Sender
TObject
TShiftState
MousePos
TPoint
Handled
Boolean
TContextPopupEvent
Sender
TObject
MousePos
TPoint
Handled
Boolean
TControl
TControl
Controls
Width<
Height
Cursor
HelpType
HelpKeyword
HelpContext,rC
TWinControlActionLink
TImeMode
imDisable
imClose
imOpen
imDontCare
imSAlpha
imAlpha
imHira
imSKata
imKata
imChinese
imSHanguel
imHanguel
Controls
TImeName
TBorderWidth
TBevelCut
bvNone
bvLowered
bvRaised
bvSpace
Controls
TBevelEdge
beLeft
beRight
beBottom
Controls
TBevelEdges
TBevelKind
bkNone
bkTile
bkSoft
bkFlat
Controls
IDockManager4
Controls
TWinControl
TWinControl
Controls
TCustomControl
TCustomControl
Controls
THintWindow
THintWindow
Controls
TDockZone
TDockTree
TMouse
crDefault
crArrow
crCross
crIBeam
crSizeNESW
crSizeNS
crSizeNWSE
crSizeWE
crUpArrow
crHourGlass
crDrag
crNoDrop
crHSplit
crVSplit
crMultiDrag
crSQLWait
crAppStart
crHelp
crHandPoint
crSizeAll
crSize
TSiteList
_^[YY]
S$_^[]
YZ]_^[
t%Jt?Jt[
%s (%s)
YZ]_^[
u$;~|u
tr;s@u
;CLtX3
_^[YY]
;s0t=;
IsControl
_^[YY]
_^[YY]
+WH+W@
:GauOFKu
DesignSize
_^[YY]
_^[YY]
_^[YY]
YZ]_^[
YZ]_^[
YZ]_^[
YZ]_^[
S8_^[]
t9;wlt4
t$;C8u
QQQQSVW
t#;^dt
BP_^[]
USER32
WINNLSEnableIME
imm32.dll
ImmGetContext
ImmReleaseContext
ImmGetConversionStatus
ImmSetConversionStatus
ImmSetOpenStatus
ImmSetCompositionWindow
ImmSetCompositionFontA
ImmGetCompositionStringA
ImmIsIME
ImmNotifyIME
Delphi%.8X
ControlOfs%.8X%.8X
USER32
AnimateWindow
TContainedAction
TContainedAction@fD
ActnList
Category
TActionEvent
Action
TBasicAction
Handled
Boolean
TCustomActionList
TCustomActionList
ActnList
TShortCutList
TShortCutList
ActnList
TCustomAction
TCustomAction
ActnList
TActionLinkSV
u*;~8u
R0Z_^[
$:Cjt_
R0Z_^[
R0]_^[
$;Ctt?
R0Z_^[
R0Z_^[
R0Z_^[
R0Z_^[
R0]_^[
$Z]_^[
TChangeLink0yD
TImageIndex
TCustomImageList
TCustomImageList
ImgList
S0_^[]
R ;C0|
R,;C4}!
S`]_^[
Bitmap
comctl32.dll
comctl32.dll
ImageList_WriteEx
EMenuError
TMenuBreak
mbNone
mbBreak
mbBarBreak
TMenuChangeEvent
Sender
TObject
Source
TMenuItem
Rebuild
Boolean
TMenuDrawItemEvent
Sender
TObject
ACanvas
TCanvas
Selected
Boolean
TAdvancedMenuDrawItemEvent
Sender
TObject
ACanvas
TCanvas
TOwnerDrawState
TMenuMeasureItemEvent
Sender
TObject
ACanvas
TCanvas
Integer
Height
Integer
TMenuItemAutoFlag
maAutomatic
maManual
maParent
Menus@
TMenuAutoFlag
TMenuActionLink
TMenuItem$
TMenuItem
Action
AutoCheck
AutoHotkeys
AutoLineReduction(?B
Bitmap
Caption
Checked
SubMenuImages
Default
EnabledT
GroupIndex
HelpContext
Hint,yD
ImageIndex
RadioItem
ShortCut
Visible
OnClick
OnDrawItem
OnAdvancedDrawItem
OnMeasureItem
TMainMenu
TMainMenu
AutoHotkeys<
AutoLineReduction
AutoMerge
BiDiMode
Images
OwnerDraw
ParentBiDiModeH
OnChange
TPopupAlignment
paLeft
paRight
paCenter
Menusx
TTrackButton
tbRightButton
tbLeftButton
TMenuAnimations
maLeftToRight
maRightToLeft
maTopToBottom
maBottomToTop
maNone
TMenuAnimation
TPopupMenu
TPopupMenu
Alignment<
AutoHotkeys<
AutoLineReduction
AutoPopup
BiDiMode
HelpContext
Images
MenuAnimation
OwnerDraw
ParentBiDiModet
TrackButtonH
OnChange
OnPopup
TPopupList
TMenuItemStack
1234567890ABCDEFGHIJKLMNOPQRSTUVWXYZ
_^[YY]
Q<]_^[
ShortCutText
P?:S?u
Q<]_^[
@?:F?v
Q<]_^[
$YZ]_^[
_^[YY]
Ih;J4u
YZ]_^[
TScrollBarInc
TScrollBarStyle
ssRegular
ssFlat
ssHotTrack
TControlScrollBar
TControlScrollBar
ButtonSizex1B
Incrementh
Margin
ParentColor<
Position<
Smooth<
Style<
ThumbSize
Tracking
Visible
TWindowState
wsNormal
wsMinimized
wsMaximized
TScrollingWinControl
TScrollingWinControl4
HorzScrollBar
VertScrollBar
TFormBorderStyle
bsNone
bsSingle
bsSizeable
bsDialog
bsToolWindow
bsSizeToolWin
Forms,
TBorderStyle
IDesignerHook$
IOleForm4
TFormStyle
fsNormal
fsMDIChild
fsMDIForm
fsStayOnTop
TBorderIcon
biSystemMenu
biMinimize
biMaximize
biHelp
TBorderIcons
TPosition
poDesigned
poDefault
poDefaultPosOnly
poDefaultSizeOnly
poScreenCenter
poDesktopCenter
poMainFormCenter
poOwnerFormCenter
TDefaultMonitor
dmDesktop
dmPrimary
dmMainForm
dmActiveForm
Forms`
TPrintScale
poNone
poProportional
poPrintToFit
TCloseAction
caNone
caHide
caFree
caMinimize
TCloseEvent
Sender
TObject
Action
TCloseAction
TCloseQueryEvent
Sender
TObject
CanClose
Boolean
TShortCutEvent
TWMKey
Handled
Boolean
THelpEvent
Command
Integer
CallHelp
Boolean
Boolean
TCustomForm
TCustomFormX
TForm\
FormsU
ActionLxC
ActiveControl
AlphaBlendT
AlphaBlendValue
Anchors
AutoScroll
AutoSize
BiDiModeT
BorderIcons
BorderStyle`sC
BorderWidth
Caption<
ClientHeight<
ClientWidthx1B
TransparentColorx1B
TransparentColorValue
Constraints
UseDockManager
DefaultMonitor
DockSiteDdC
DragKind
DragMode
Enabled
ParentFont
FormStyle<
Height
HelpFile
HorzScrollBar`@B
KeyPreview
OldCreateOrder
ObjectMenuItem
ParentBiDiMode<
PixelsPerInch
PopupMenul
Position\
PrintScale
Scaled
ScreenSnap
ShowHint<
SnapBuffer
VertScrollBar
Visible<
WindowState
WindowMenu
OnActivatexkC
OnCanResize
OnClick
OnClose0
OnCloseQuery
OnConstrainedResizetmC
OnContextPopup
OnCreate
OnDblClick
OnDestroy
OnDeactivate<iC
OnDockDrop
OnDockOver8hC
OnDragDrop
OnDragOver
OnEndDock
OnGetSiteInfo
OnHide
OnHelp(gC
OnKeyDowntgC
OnKeyPress(gC
OnKeyUpLfC
OnMouseDown
OnMouseMoveLfC
OnMouseUpxlC
OnMouseWheel
OnMouseWheelDown
OnMouseWheelUp
OnPaint
OnResizet
OnShortCut
OnShow
OnStartDock4jC
OnUnDock
TCustomDockForm<
TCustomDockForm
PixelsPerInch
TMonitor
TScreen
TScreen,
THintInfo@
TMessageEvent
tagMSG
Handled
Boolean
TExceptionEvent
Sender
TObject
Exception
TIdleEvent
Sender
TObject
Boolean
TShowHintEvent
HintStr
String
CanShow
Boolean
HintInfo
THintInfo
TSettingChangeEvent
Sender
TObject
Integer
Section
String
Result
Integer
TApplication
TApplication
;X0t@S
+WH+W@
PixelsPerInch
TextHeight
IgnoreFontProperty
_^[YY]
S,_^[]
$Z]_^[
F(Z_^[
MDICLIENT
_^[YY]
_^[YY]
_^[YY]
Ch;Ctt
Cd;Cpt
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
layout text
f;sDtsf
CHYZ]_^[
_^[YY]
TApplication
MAINICON
XD;PHu
sx;P`u
;B0uGj
_^[YY]
vcltest3.dll
RegisterAutomation
t;s0t
$Z]_^[
~D_^[Y]
Y_^[Y]
YZ]_^[
User32.dll
SetLayeredWindowAttributes
TaskbarCreated
TCustomApplicationEvents
TCustomApplicationEventsh
AppEvnts
TApplicationEvents
TApplicationEvents4
AppEvnts
OnActionExecute
OnActionUpdate
OnActivate
OnDeactivate
OnException4
OnIdle
OnHelp
OnHint
OnMessage
OnMinimize
OnRestorep
OnShowHintt
OnShortCut
OnSettingChange
TMultiCaster
TMultiCaster
AppEvnts
_^[YY]
TOrtusShellFolder
TOrtusShellSpecialFolder
sfDesktop
sfInternet
sfPrograms
sfControls
sfPrinters
sfPersonal
sfFavorites
sfStartUp
sfRecent
sfSendTo
sfBitBucket
sfStartMenu
sfDesktopDirectory
sfDrives
sfNetWork
sfNetHood
sfFonts
sfTemplates
sfCommonStartMenu
sfCommonPrograms
sfCommonStartUp
sfCommonDesktopDirectory
sfAppData
sfPrintHood
sfAltStartUp
sfCommonAltStartUp
sfCommonFavorites
sfInternetCache
sfCookies
sfHistory
OrtusShellGlobal
sfDesktop
sfInternet
sfPrograms
sfControls
sfPrinters
sfPersonal
sfFavorites
sfStartUp
sfRecent
sfSendTo
sfBitBucket
sfStartMenu
sfDesktopDirectory
sfDrives
sfNetWork
sfNetHood
sfFonts
sfTemplates
sfCommonStartMenu
sfCommonPrograms
sfCommonStartUp
sfCommonDesktopDirectory
sfAppData
sfPrintHood
sfAltStartUp
sfCommonAltStartUp
sfCommonFavorites
sfInternetCache
sfCookies
sfHistory
*TOrtusShellChangeNotifierAssocChangedEvent
Sender
TObject
TriggeredBySystemInterrupt
Boolean
(TOrtusShellChangeNotifierAttributesEvent
Sender
TObject
ItemName
String
TriggeredBySystemInterrupt
Boolean
$TOrtusShellChangeNotifierCreateEvent
Sender
TObject
ItemName
String
TriggeredBySystemInterrupt
Boolean
$TOrtusShellChangeNotifierDeleteEvent
Sender
TObject
ItemName
String
TriggeredBySystemInterrupt
Boolean
&TOrtusShellChangeNotifierDriveAddEvent
Sender
TObject
ItemName
String
TriggeredBySystemInterrupt
Boolean
)TOrtusShellChangeNotifierDriveAddGUIEvent
Sender
TObject
ItemName
String
TriggeredBySystemInterrupt
Boolean
*TOrtusShellChangeNotifierDriveRemovedEvent
Sender
TObject
ItemName
String
TriggeredBySystemInterrupt
Boolean
'TOrtusShellChangeNotifierFreeSpaceEvent
Sender
TObject
ItemName
String
TriggeredBySystemInterrupt
Boolean
+TOrtusShellChangeNotifierMediaInsertedEvent
Sender
TObject
ItemName
String
TriggeredBySystemInterrupt
Boolean
*TOrtusShellChangeNotifierMediaRemovedEvent
Sender
TObject
ItemName
String
TriggeredBySystemInterrupt
Boolean
#TOrtusShellChangeNotifierMkDirEvent
Sender
TObject
ItemName
String
TriggeredBySystemInterrupt
Boolean
&TOrtusShellChangeNotifierNetShareEvent
Sender
TObject
ItemName
String
TriggeredBySystemInterrupt
Boolean
(TOrtusShellChangeNotifierNetUnshareEvent
Sender
TObject
ItemName
String
TriggeredBySystemInterrupt
Boolean
*TOrtusShellChangeNotifierRenameFolderEvent
Sender
TObject
OldItemName
String
NewItemName
String
TriggeredBySystemInterrupt
Boolean
(TOrtusShellChangeNotifierRenameItemEvent
Sender
TObject
OldItemName
String
NewItemName
String
TriggeredBySystemInterrupt
Boolean
#TOrtusShellChangeNotifierRmDirEvent
Sender
TObject
ItemName
String
TriggeredBySystemInterrupt
Boolean
.TOrtusShellChangeNotifierServerDisconnectEvent
Sender
TObject
ItemName
String
TriggeredBySystemInterrupt
Boolean
'TOrtusShellChangeNotifierUpdateDirEvent
Sender
TObject
ItemName
String
TriggeredBySystemInterrupt
Boolean
)TOrtusShellChangeNotifierUpdateImageEvent
Sender
TObject
ItemName
String
TriggeredBySystemInterrupt
Boolean
(TOrtusShellChangeNotifierUpdateItemEvent
Sender
TObject
ItemName
String
TriggeredBySystemInterrupt
Boolean
TOrtusShellChangeNotifierItem
TCustomOrtusShellChangeNotifier
TCustomOrtusShellChangeNotifier
OrtusShellChangeNotifier
TOrtusShellChangeNotifierFolder
TOrtusShellChangeNotifierFolder
OrtusShellChangeNotifier
Folder
WatchSubTree
TOrtusShellChangeNotifierFolders
TOrtusShellChangeNotifierFolders
OrtusShellChangeNotifier
TOrtusShellChangeNotifier
TOrtusShellChangeNotifier
OrtusShellChangeNotifier
Active
OnAssocChanged
OnAttributes
OnCreate$
OnDelete
OnDriveAdd$
OnDriveAddGUI
OnDriveRemoved,
OnFreeSpace
OnMediaInserted8
OnMediaRemoved
OnMkDir<
OnNetShare
OnNetUnshare@
OnRenameFolder
OnRenameItem
OnRmDir
OnServerDisconnect
OnUpdateDir
OnUpdateImage
OnUpdateItem`
Folders
_^[YY]
MsgId_OrtusShellChangeNotifier
SHELL32.DLL
TJPEGData
TJPEGImage
TJPEGImage8
S\_^[]
S`_^[Y]
FD_^[Y]
FH_^[Y]
YZ]_^[
K,;K(u
T$$;L$
D$$;T$
L$ ;\$
L$,;T$
L$(;\$
L$0;T$
L$4;T$
L$8;T$
L$<;T$
D$D;T$
L$@;\$
D$,;L$
T$(;\$
K4_^[YY]
C4;CHr3
_^[YY]
D$ ;CH}4
;t$(}(
{$F;t$(|
L$ ;K8|
D$ H;D$
D$p+D$x+
Jt\Jt;
YZ]_^[
EKG;|$
YZ]_^[
_^[YY]
P ;S0uP3
K4;K<}53
C4;C<uV
OtAOt
C4;D$$~u
D$ ;D$$
D$ ;D$$
P@YZ]_^[
_^[YY]
K<;K(u
C8;C$t
YZ]_^[
kernel32.dll
CreateToolhelp32Snapshot
Heap32ListFirst
Heap32ListNext
Heap32First
Heap32Next
Toolhelp32ReadProcessMemory
Process32First
Process32Next
Process32FirstW
Process32NextW
Thread32First
Thread32Next
Module32First
Module32Next
Module32FirstW
Module32NextW
abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ123456789
Unknown
Ht!Ht,
Unknown (Windows
tIh 3G
shell32.dll
SHGetKnownFolderPath
{374DE290-123F-4565-9164-39C4925E467B}
\Downloads
klenenler
Software\Microsoft\Windows\CurrentVersion\Run
Software\
C ;C$s
QQQQQQSVW
Invalid root path
Removable
Remote (network)
CD-ROM
RAM disk
Unknown
Directory
CompanyName
FileDescription
FileVersion
InternalName
LegalCopyRight
OriginalFileName
ProductName
ProductVersion
\VarFileInfo\Translation
\StringFileInfo\%0.4x%0.4x\%s
_^[YY]
Error 404
Not Found
cmd.exe /C
*
00-00-00-00-00-00
SeSystemProfilePrivilege
$000000.tmp
$000000.tmp
TKBLogger
TKBLogger
KBLogger
\WinSl
HookOn
HookOff
DLL Fonksiyonu Bulunamad
ElReceptor
Dosya Olu
turulamad
CBReceptor
QQQQQS3
Active ->
_^[YY]
Completed ->
Vrs Updated ->
Infected Canceled ->
Completed ->
Vrs Updated ->
Injected Canceled->
._cache_
EOleError
EOleSysError
EOleException
Apartment
Neutral
ole32.dll
CoCreateInstanceEx
CoInitializeEx
CoAddRefServerProcess
CoReleaseServerProcess
CoResumeClassObjects
CoSuspendClassObjects
QQQQQQQQSV
QQQQQ3
Excel.Application
DisplayAlerts
EnableEvents
Visible
Excel.Application
DisplayAlerts
EnableEvents
Visible
Workbooks
Worksheets
Workbooks
Worksheets
Select
Worksheets
Delete
SelectedSheets
ActiveWindow
\~$cache1
QQQQQSVW
Completed ->
EIdException
EIdSilentException
EIdConnClosedGracefully|
EIdAlreadyConnected
EIdClosedSocket8
EIdReadTimeout
EIdReadLnMaxLineLengthExceeded
EIdInvalidServiceName
EIdProtocolReplyError
EIdConnectTimeout
EIdConnectException
EIdSocksError
EIdSocksRequestFailed
EIdSocksRequestServerFailed
EIdSocksRequestIdentFailed
EIdSocksUnknownError
EIdSocksServerRespondError
EIdSocksAuthMethodErrorL
EIdSocksAuthError
EIdSocksServerGeneralError
EIdSocksServerPermissionError
!EIdSocksServerNetUnreachableError
"EIdSocksServerHostUnreachableError
$EIdSocksServerConnectionRefusedError
EIdSocksServerTTLExpiredError
EIdSocksServerCommandError
EIdSocksServerAddressError
EIdInvalidSocket
EIdSocketError
EIdWS2StubError
WSACleanup
accept
closesocket
connect
ioctlsocket
getpeername
getsockname
getsockopt
inet_addr
inet_ntoa
listen
recvfrom
select
sendto
setsockopt
shutdown
socket
gethostbyaddr
gethostbyname
gethostname
getservbyport
getservbyname
getprotobynumber
getprotobyname
WSASetLastError
WSAGetLastError
WSAIsBlocking
WSAUnhookBlockingHook
WSASetBlockingHook
WSACancelBlockingCall
WSAAsyncGetServByName
WSAAsyncGetServByPort
WSAAsyncGetProtoByName
WSAAsyncGetProtoByNumber
WSAAsyncGetHostByName
WSAAsyncGetHostByAddr
WSACancelAsyncRequest
WSAAsyncSelect
__WSAFDIsSet
WSAAccept
WSACloseEvent
WSAConnect
WSACreateEvent
WSADuplicateSocketA
WSADuplicateSocketW
WSAEnumNetworkEvents
WSAEnumProtocolsA
WSAEnumProtocolsW
WSAEventSelect
WSAGetOverlappedResult
WSAGetQosByName
WSAHtonl
WSAHtons
WSAIoctl
WSAJoinLeaf
WSANtohl
WSANtohs
WSARecv
WSARecvDisconnect
WSARecvFrom
WSAResetEvent
WSASend
WSASendDisconnect
WSASendTo
WSASetEvent
WSASocketA
WSASocketW
WSAWaitForMultipleEvents
WSAAddressToStringA
WSAAddressToStringW
WSAStringToAddressA
WSAStringToAddressW
WSALookupServiceBeginA
WSALookupServiceBeginW
WSALookupServiceNextA
WSALookupServiceNextW
WSALookupServiceEnd
WSAInstallServiceClassA
WSAInstallServiceClassW
WSARemoveServiceClass
WSAGetServiceClassInfoA
WSAGetServiceClassInfoW
WSAEnumNameSpaceProvidersA
WSAEnumNameSpaceProvidersW
WSAGetServiceClassNameByClassIdA
WSAGetServiceClassNameByClassIdW
Antivirus Signature
Bkav W32.HanGu.PE
Lionic Virus.Win32.Neshta.tntj
tehtris Generic.Malware
ClamAV Win.Trojan.Emotet-9850453-0
CMC Clean
CAT-QuickHeal W32.Neshta.B
Skyhigh BehavesLike.Win32.HLLP.ch
McAfee W32/HLLP.41472
Cylance Unsafe
Zillya Virus.Neshta.Win32.2
Sangfor Virus.Win32.Neshta.a
K7AntiVirus Virus ( 00556e571 )
Alibaba Virus:Win32/Neshta.3bb
K7GW Virus ( 00556e571 )
Cybereason malicious.674c67
Baidu Win32.Virus.Neshta.a
Paloalto generic.ml
Symantec W32.Neshuta
Elastic malicious (high confidence)
ESET-NOD32 Win32/Neshta.B
APEX Malicious
Avast Other:Malware-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky Virus.Win32.Neshta.b
BitDefender Win32.Nestha.C
NANO-Antivirus Virus.Win32.Neshta.fnxshx
ViRobot Win32.Neshta.Gen.A
MicroWorld-eScan Win32.Nestha.C
Tencent Virus.Win32.Neshta.a
TACHYON Clean
Sophos W32/Neshta-D
F-Secure Trojan:W97M/MaliciousMacro.GEN
DrWeb Win32.HLLP.Neshta
VIPRE Win32.Nestha.C
TrendMicro PE_NESHTA.A
McAfeeD Real Protect-LS!2F6F4F9674C6
Trapmine malicious.high.ml.score
FireEye Generic.mg.2f6f4f9674c6721b
Emsisoft Win32.Nestha.C (B)
SentinelOne Static AI - Malicious PE
GData Win32.Nestha.C
Jiangmin Virus.Neshta.b
Webroot W32.Virus.B
Varist W32/HLLP.EPJG-6217
Avira W32/Delf.I
Antiy-AVL Virus/Win32.Neshta.b
Kingsoft Win32.Neshta.a.41472
Gridinsoft Trojan.Win32.Gen.tr
Xcitium Win32.Neshta.B@3z07
Arcabit Win32.Nestha.C
SUPERAntiSpyware Clean
ZoneAlarm Virus.Win32.Neshta.b
Microsoft Virus:Win32/Neshta.B
Google Detected
AhnLab-V3 Win32/Neshta
Acronis suspicious
ALYac Win32.Nestha.C
MAX malware (ai score=86)
VBA32 Virus.Win32.Neshta.b
Malwarebytes Generic.Malware.AI.DDS
Panda W32/Neshta.C
Zoner Virus.Win32.19514
TrendMicro-HouseCall PE_NESHTA.A
Rising Virus.Synaptics!1.E51C (CLASSIC)
Yandex Trojan.GenAsa!Mo0tdcmmg3o
Ikarus Virus.Win32.Neshta
MaxSecure Clean
Fortinet VBA/Agent.IGI!tr.dldr
BitDefenderTheta AI:FileInfector.841243EC0E
AVG Other:Malware-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Virus:Win/Neshta.A(dyn)
No IRMA results available.